Security GRC Engineer
Job in
San Ramon, Contra Costa County, California, 94583, USA
Listed on 2025-12-02
Listing for:
PriMed Management Consulting Services, Inc.
Full Time
position Listed on 2025-12-02
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Data Security
Job Description & How to Apply Below
** We’re delighted you’re considering joining us!
** At Hill Physicians Medical Group, we’re shaping the healthcare of the future: actively managed care that prevents disease, supports those with chronic conditions and anticipates the needs of our members.
** Join Our Team!
** Hill Physicians has much to offer prospective employees. We’re regularly recognized as one of the “Best Places to Work in the Bay Area” and have been recognized as one of the “Healthiest Places to Work in the Bay Area.” When you join our team, you’re making a great choice for your professional career and your personal satisfaction.
** DE&I Statement:
** At Pri Med, your uniqueness is valued, celebrated, encouraged, supported, and embraced. Whatever your relationship with Hill Physicians, we welcome ALL that you are.
We value and respect your race, ethnicity, gender identity, sexual orientation, age, religion, disabilities, experiences, perspectives, and other attributes. Our celebration of diversity and foundation of inclusion allows us to leverage our differences and capitalize on our similarities to better serve our communities. We do it because it's right!
*
* Job Description:
** We are seeking a skilled Governance, Risk, and Compliance (GRC) Engineer to strengthen our security posture and ensure adherence to healthcare regulations. The GRC Engineer will play a vital role in designing, implementing, and maintaining risk management processes, compliance frameworks, and policies that align with healthcare regulations such as HIPAA and HITECH. The ideal candidate will have experience with tools like SAI
360, Cyber Ark, and other compliance and security platforms.
*
* Job Responsibilities:
*** Develop, implement, and maintain GRC policies, processes, and controls in alignment with industry best practices and regulatory requirements (e.g., HIPAA, HITECH, NIST, ISO 27001).
* Perform risk assessments and develop mitigation strategies for identified security risks.
* Administer and optimize SAI
360 for governance, risk management, and compliance activities, including reporting and policy management.
* Collaborate with cross-functional teams to ensure new projects and systems are designed with security and compliance in mind.
* Monitor and report on compliance status, identifying gaps and proposing remediation strategies.
* Oversee third-party vendor risk assessments and ensure adherence to security requirements.
* Support internal and external audits by providing documentation, evidence, and responses to audit findings.
* Conduct security awareness training programs and promote a culture of compliance within the organization.
** Required Experience/Skills/Knowledge:
*** 5+ years of experience in Governance, Risk, and Compliance roles or a related field.
* Strong knowledge of healthcare regulations, including HIPAA, HITECH, and other relevant standards.
* Proficiency in GRC tools such as SAI
360 for compliance and risk management.
* Experience with privileged access management tools like Cyber Ark.
* Solid understanding of risk assessment methodologies and security frameworks, including NIST CSF, ISO 27001, or COBIT.
* Excellent communication and collaboration skills to engage with technical and non-technical stakeholders.
* Strong analytical and organizational skills with attention to detail.
** Preferred Experience/Skills/Knowledge:
*** Experience working in the healthcare industry or with Protected Health Information (PHI).
* Familiarity with tools such as Varonis, Extrahop, or SIEM platforms.
* Knowledge of data classification, data loss prevention (DLP), and data governance.
* Relevant certifications such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified Risk and Information Systems Control (CRISC).
* Experience implementing compliance with NIST 2.0 or managing frameworks for healthcare-related threats.
** Required
Education:
*** Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
* Equivalent work experience may be considered in lieu of a degree.
** Additional Information:
** This role is critical in maintaining our organization’s compliance with healthcare security standards and reducing risk exposure.
The position offers a collaborative environment with opportunities for professional development and certifications.
Competitive salary and benefits package, with the chance to make a significant impact on healthcare security.
Salary: $135,000 - $150,000 Annual
** Hill Physicians is an Equal Opportunity Employer*
* #J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×